Skip to main navigation Skip to search Skip to main content

A Hitchhiker's Guide to White-Box Neural Network Watermarking Robustness

  • Telecom Sudparis
  • Institut Polytechnique de Paris
  • University of Turin
  • University of Padova

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The present study deals with white-box Neural Network (NN) watermarking and focuses on the robustness property. The first contribution consists of formalizing neuron permutation as a geometric attack, thus demonstrating the very existence of this class of attacks for NN watermarking. The second contribution consists in devising and demonstrating the effectiveness of the corresponding counter-attack. As a side result, the possibility of extending NN white-box watermarking scope beyond image classification is brought to light. The experimental study considers three state-of-the-art methods, four NN models, three tasks (image classification, segmentation, and video coding), and five types of attacks. We underline that none of the existing methods is robust against the geometric attack, and using the counter-attack advanced in this paper effectively ensures the robustness.

Original languageEnglish
Title of host publication2023 11th European Workshop on Visual Information Processing, EUVIP 2023 - Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798350342185
DOIs
Publication statusPublished - 1 Jan 2023
Event11th European Workshop on Visual Information Processing, EUVIP 2023 - Gjovik, Norway
Duration: 11 Sept 202314 Sept 2023

Publication series

NameProceedings - European Workshop on Visual Information Processing, EUVIP
ISSN (Print)2471-8963

Conference

Conference11th European Workshop on Visual Information Processing, EUVIP 2023
Country/TerritoryNorway
CityGjovik
Period11/09/2314/09/23

Keywords

  • counter-attack
  • geometric attacks
  • neural network
  • robustness
  • watermarking
  • white-box

Fingerprint

Dive into the research topics of 'A Hitchhiker's Guide to White-Box Neural Network Watermarking Robustness'. Together they form a unique fingerprint.

Cite this